Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15445 | MEDIUM | 4.9 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due … | Jul 16, 2026 |
| CVE-2026-15306 | MEDIUM | 6.1 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter … | Jul 16, 2026 |
| CVE-2026-15013 | CRITICAL | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up … | Jul 16, 2026 |
| CVE-2026-13042 | HIGH | 7.2 | The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to … | Jul 16, 2026 |
| CVE-2026-21729 | HIGH | 7.5 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. | Jul 16, 2026 |
| CVE-2026-15652 | MEDIUM | 6.4 | The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in … | Jul 16, 2026 |
| CVE-2026-15336 | MEDIUM | 4.3 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the … | Jul 16, 2026 |
| CVE-2026-14987 | MEDIUM | 6.4 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions … | Jul 16, 2026 |
| CVE-2026-13005 | MEDIUM | 4.4 | The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | Jul 16, 2026 |
| CVE-2026-12941 | MEDIUM | 6.5 | The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions … | Jul 16, 2026 |
| CVE-2026-12753 | HIGH | 7.5 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter … | Jul 16, 2026 |
| CVE-2026-12434 | MEDIUM | 4.3 | The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This … | Jul 16, 2026 |
| CVE-2026-12409 | MEDIUM | 4.3 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in … | Jul 16, 2026 |
| CVE-2026-48863 | HIGH | 7.5 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA … | Jul 16, 2026 |
| CVE-2026-3842 | HIGH | 7.8 | A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This … | Jul 16, 2026 |
| CVE-2026-23538 | HIGH | 7.5 | A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening … | Jul 16, 2026 |
| CVE-2026-1609 | HIGH | 8.1 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak … | Jul 16, 2026 |
| CVE-2026-15909 | MEDIUM | 6.3 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument … | Jul 16, 2026 |
| CVE-2026-15907 | HIGH | 7.3 | A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of … | Jul 16, 2026 |
| CVE-2026-63175 | UNKNOWN | — | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process … | Jul 15, 2026 |
| CVE-2026-62314 | MEDIUM | 5.8 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go … | Jul 15, 2026 |
| CVE-2026-55652 | CRITICAL | 9.8 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before … | Jul 15, 2026 |
| CVE-2026-55576 | UNKNOWN | — | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the … | Jul 15, 2026 |
| CVE-2026-55445 | UNKNOWN | — | Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but … | Jul 15, 2026 |
| CVE-2026-55234 | HIGH | 8.5 | Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored … | Jul 15, 2026 |